Elium · Vulnerability Disclosure

Elium Vulnerability Disclosure

Vulnerability disclosure

Elium runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySoftware-as-a-ServiceKnowledge-ManagementKnowledge BaseEnterprise SearchAI SearchGraphQLMCPCollaborationDocumentationRAGEurope
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@elium.com

Source

Vulnerability Disclosure

elium-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-17'
method: searched
probe: true
source: https://elium.com/trust/controls
policy: []
policy_published: false
contact: [security@elium.com]
contact_url: https://elium.com/trust/controls
bug_bounty: null
finding: >-
  Elium publishes a security contact and a public security-controls page, but NO responsible-disclosure
  policy and NO bug-bounty programme. security@elium.com is presented as a general security-team mailbox
  ("handles vendor reviews, RFPs, audits, and architecture questions"), not as a vulnerability intake with
  scope, safe-harbour terms, or response targets. A researcher has an address to write to and nothing that
  tells them the rules. Recorded honestly: a reachable channel, an absent programme.
what_exists:
- {item: security contact, value: 'security@elium.com', source: 'https://elium.com/trust'}
- {item: public security-controls page, value: 'https://elium.com/trust/controls'}
- item: third-party penetration testing
  value: >-
    "Penetration tests are conducted regularly by independent third parties and vulnerability scans are
    automated. Findings are assessed and remediated per defined SLAs."
  source: https://elium.com/trust/controls
- item: penetration-test reports
  value: 2025 and 2024 reports listed as documents available on request
  source: https://elium.com/trust
- item: incident-response programme with acknowledgement/resolution SLAs
  source: https://elium.com/trust/controls
what_is_missing:
- No /.well-known/security.txt (RFC 9116) on elium.com or api.elium.com - both 404.
- No responsible-disclosure or vulnerability-disclosure page - /security and /responsible-disclosure both 404.
- No HackerOne, Bugcrowd, Intigriti, YesWeHack or self-hosted bounty programme found.
- No stated scope, safe harbour, PGP key, or researcher response-time commitment.
false_positive_rejected:
  url: https://help.elium.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain
  verdict: rejected
  reason: >-
    This is INTERCOM's security.txt, served because Elium's help centre is Intercom-hosted. Its own Canonical
    field is https://app.intercom.com/.well-known/security.txt and its contacts are bugcrowd.com/intercom and
    security@intercom.com. Crediting it to Elium would attribute another company's bug-bounty programme to
    them, so it is deliberately not saved and no SecurityTxt pointer is wired.
evidence:
- {source: 'https://elium.com/trust', http_status: 200, kind: security-contact, probed: '2026-08-17'}
- {source: 'https://elium.com/trust/controls', http_status: 200, kind: security-policy-page, probed: '2026-08-17'}
- {source: 'https://elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://api.elium.com/.well-known/security.txt', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://elium.com/security', http_status: 404, kind: absent, probed: '2026-08-17'}
- {source: 'https://elium.com/responsible-disclosure', http_status: 404, kind: absent, probed: '2026-08-17'}
recommendation: >-
  Publishing /.well-known/security.txt on elium.com pointing at security@elium.com and a short disclosure
  page would cost Elium almost nothing and is the single cheapest security-transparency gap on this profile.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/elium-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.